Логотип exploitDog
bind:CVE-2021-43795
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-43795

Количество 2

Количество 2

nvd логотип

CVE-2021-43795

около 4 лет назад

Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8fp4-rp6c-5gcv

около 4 лет назад

Path Traversal in com.linecorp.armeria:armeria

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-43795

Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-8fp4-rp6c-5gcv

Path Traversal in com.linecorp.armeria:armeria

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу